The private agent start command no longer contains your runner key
The docker run command shown when you create a runner key now reads the key from your shell and names a fixed agent release.
When you create a runner key, the dashboard and the CLI show a docker run
command for starting an agent. Two things about it have changed.
The key is no longer written into the command. It used to appear as
-e RUNNER_API_KEY=rk_..., which left it in your shell history and visible in
the process list while Docker started. The command now comes in two steps. The
first reads the key into your shell without showing it. The second starts the
agent and tells Docker to pick the key up from there. If you skip the first
step, the second stops with a message instead of starting an agent that has no
key.
The image is a fixed release, not latest. The command names the current
agent version together with the digest of its image, so running it again next
month starts exactly the same agent. A digest identifies the image contents, so
Docker refuses anything else published under that name. To move a
docker run agent to a newer release, create a new runner key, which comes
with the command for the current version, then remove the old container and
revoke the old key. The steps are in
Updating the agent.
Agents started with the Compose file are unaffected. Their key was already
kept in .env.
The dashboard change is live now. In the CLI it is in @yorker/cli@0.10.2.